Removing a user from an upstream group in Azure AD was not causing that user to be removed correctly from the downstream Django group. This happens when a user is removed from an existing mapped Azure group and no longer has any roles in id_token_claims as a result.
Removing a user from an upstream group in Azure AD was not causing that user to be removed correctly from the downstream Django group. This happens when a user is removed from an existing mapped Azure group and no longer has any roles in id_token_claims as a result.